Answer in brief
CVE-2023-52752 records a Unknown severity vulnerability in smb: client: fix use-after-free bug in cifs_debug_data_proc_show(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), linux/linux_kernel (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2023-52752 records a Unknown severity vulnerability in smb: client: fix use-after-free bug in cifs_debug_data_proc_show(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), linux/linux_kernel (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), linux/linux_kernel (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7f48558e6489d032b1584b0cc9ac4bb11072c034 <2abdf136784b7edaec7ffe0f4b461b63f9c4c4de || >=7f48558e6489d032b1584b0cc9ac4bb11072c034 <336a066990bb3962c46daf574ace596bda9303ce || >=7f48558e6489d032b1584b0cc9ac4bb11072c034 <558817597d5fbd7af31f891b67b0fd20f0d047b7 || >=7f48558e6489d032b1584b0cc9ac4bb11072c034 <89929ea46f9cc11ba66d2c64713aa5d5dc723b09 || >=7f48558e6489d032b1584b0cc9ac4bb11072c034 <0ab6f842452ce2cae04209d4671ac6289d0aef8a || >=7f48558e6489d032b1584b0cc9ac4bb11072c034 <d328c09ee9f15ee5a26431f5aad7c9239fa85e62 || a67172a013953664b1dad03c648200c70b90506c || >=3.12.48 <3.13 | 2abdf136784b7edaec7ffe0f4b461b63f9c4c4de, 336a066990bb3962c46daf574ace596bda9303ce, 558817597d5fbd7af31f891b67b0fd20f0d047b7, 89929ea46f9cc11ba66d2c64713aa5d5dc723b09, 0ab6f842452ce2cae04209d4671ac6289d0aef8a, d328c09ee9f15ee5a26431f5aad7c9239fa85e62, 3.13 |
| Linux/Linuxgeneric | 3.13 | Not reported |
| linux/linux_kernelgeneric | 1da177e4c3f4 | Not reported |
Published upstream
May 21, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free bug in cifs_debug_data_proc_show() Skip SMB sessions that are being teared down (e.g. @ses->ses_status == SES_EXITING) in cifs_debug_data_proc_show() to avoid use-after-free in @ses. This fixes the following GPF when reading from /proc/fs/cifs/DebugData while mounting and umounting [ 816.251274] general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6d81: 0000 [#1] PREEMPT SMP NOPTI ... [ 816.260138] Call Trace: [ 816.260329] <TASK> [ 816.260499] ? die_addr+0x36/0x90 [ 816.260762] ? exc_general_protection+0x1b3/0x410 [ 816.261126] ? asm_exc_general_protection+0x26/0x30 [ 816.261502] ? cifs_debug_tcon+0xbd/0x240 [cifs] [ 816.261878] ? cifs_debug_tcon+0xab/0x240 [cifs] [ 816.262249] cifs_debug_data_proc_show+0x516/0xdb0 [cifs] [ 816.262689] ? seq_read_iter+0x379/0x470 [ 816.262995] seq_read_iter+0x118/0x470 [ 816.263291] proc_reg_read_iter+0x53/0x90 [ 816.263596] ? srso_alias_return_thunk+0x5/0x7f [ 816.263945] vfs_read+0x201/0x350 [ 816.264211] ksys_read+0x75/0x100 [ 816.264472] do_syscall_64+0x3f/0x90 [ 816.264750] entry_SYSCALL_64_after_hwframe+0x6e/0xd8 [ 816.265135] RIP: 0033:0x7fd5e669d381
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), linux/linux_kernel (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7f48558e6489d032b1584b0cc9ac4bb11072c034 <2abdf136784b7edaec7ffe0f4b461b63f9c4c4de || >=7f48558e6489d032b1584b0cc9ac4bb11072c034 <336a066990bb3962c46daf574ace596bda9303ce || >=7f48558e6489d032b1584b0cc9ac4bb11072c034 <558817597d5fbd7af31f891b67b0fd20f0d047b7 || >=7f48558e6489d032b1584b0cc9ac4bb11072c034 <89929ea46f9cc11ba66d2c64713aa5d5dc723b09 || >=7f48558e6489d032b1584b0cc9ac4bb11072c034 <0ab6f842452ce2cae04209d4671ac6289d0aef8a || >=7f48558e6489d032b1584b0cc9ac4bb11072c034 <d328c09ee9f15ee5a26431f5aad7c9239fa85e62 || a67172a013953664b1dad03c648200c70b90506c || >=3.12.48 <3.13 | 2abdf136784b7edaec7ffe0f4b461b63f9c4c4de, 336a066990bb3962c46daf574ace596bda9303ce, 558817597d5fbd7af31f891b67b0fd20f0d047b7, 89929ea46f9cc11ba66d2c64713aa5d5dc723b09, 0ab6f842452ce2cae04209d4671ac6289d0aef8a, d328c09ee9f15ee5a26431f5aad7c9239fa85e62, 3.13 |
| Linux/Linuxgeneric | 3.13 | Not reported |
| linux/linux_kernelgeneric | 1da177e4c3f4 | Not reported |
Published upstream
May 21, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free bug in cifs_debug_data_proc_show() Skip SMB sessions that are being teared down (e.g. @ses->ses_status == SES_EXITING) in cifs_debug_data_proc_show() to avoid use-after-free in @ses. This fixes the following GPF when reading from /proc/fs/cifs/DebugData while mounting and umounting [ 816.251274] general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6d81: 0000 [#1] PREEMPT SMP NOPTI ... [ 816.260138] Call Trace: [ 816.260329] <TASK> [ 816.260499] ? die_addr+0x36/0x90 [ 816.260762] ? exc_general_protection+0x1b3/0x410 [ 816.261126] ? asm_exc_general_protection+0x26/0x30 [ 816.261502] ? cifs_debug_tcon+0xbd/0x240 [cifs] [ 816.261878] ? cifs_debug_tcon+0xab/0x240 [cifs] [ 816.262249] cifs_debug_data_proc_show+0x516/0xdb0 [cifs] [ 816.262689] ? seq_read_iter+0x379/0x470 [ 816.262995] seq_read_iter+0x118/0x470 [ 816.263291] proc_reg_read_iter+0x53/0x90 [ 816.263596] ? srso_alias_return_thunk+0x5/0x7f [ 816.263945] vfs_read+0x201/0x350 [ 816.264211] ksys_read+0x75/0x100 [ 816.264472] do_syscall_64+0x3f/0x90 [ 816.264750] entry_SYSCALL_64_after_hwframe+0x6e/0xd8 [ 816.265135] RIP: 0033:0x7fd5e669d381
Quoted source text, attributed separately from HOL analysis.